Microsoft To Do and MCP: Can Claude Manage Your List?
Microsoft ships several MCP servers, but none of them is a To Do server. What Microsoft does offer, what Claude’s Microsoft 365 connector covers, the Graph API that community servers wrap, the risks of those servers, and when a shared board is the better fit.
Updated 7 min read
Not through anything Microsoft ships specifically for it. At the end of September 2026, Microsoft’s MCP servers cover things such as mail, calendar, files, Teams, people and directory data, and none of them is a Microsoft To Do server. Claude’s own Microsoft 365 connector covers SharePoint, OneDrive, Outlook and Teams, and does not list To Do either. What does exist is the Microsoft Graph To Do API, which several open-source MCP servers wrap. So Claude can manage your To Do list, but only through a server you install and trust yourself, and that trust is the part worth thinking about.
This moves quickly, so check the pages linked below before you rely on any of it. If MCP itself is new to you, what MCP is is the place to start.
What Microsoft ships for MCP today
Microsoft has three things with MCP in the name that people reasonably mistake for a To Do route. None of them is one, for different reasons.
- Work IQ MCP servers. The Agent 365 tools catalog (opens in a new tab) lists servers for Microsoft 365 Copilot, Calendar, Mail, SharePoint, OneDrive, Teams, User and Word, plus Dataverse and a few others. There is no To Do server and no Planner server in that list. They run in an organisation’s Microsoft Entra tenant, and admins switch them on or off in the Microsoft 365 admin center.
- The Work IQ MCP endpoint. This is one server with ten generic tools, such as
fetch,create_entityandupdate_entity, that act on Microsoft Graph resource paths. Microsoft describes it as covering mail, calendar, files, people, chat and sites. - Microsoft MCP Server for Enterprise. Despite the broad name, the Graph documentation (opens in a new tab) says it focuses on read-only Microsoft Entra identity and directory questions: users, groups, applications, devices and admin reporting. It is in preview, and it does not touch anyone’s tasks.
Could the generic Work IQ tools reach To Do?
Possibly, but Microsoft does not document it as a To Do route. The generic tools work on Graph v1.0 paths, /me/ paths are allowed by default, and To Do’s API lives under /me/todo. On paper, an agent could read your lists that way. In practice, the Work IQ tool reference (opens in a new tab) says a tenant policy layer blocks create, update and delete requests by default until an administrator enables them, and that the allowed and blocked paths depend on each tenant’s policy.
It is also an organisational service: it needs a work or school account on a Microsoft Entra tenant, and connecting a coding agent such as Claude Code means registering an application in Entra first. If your company already runs Work IQ and you want To Do through it, that is a question for your Microsoft 365 admin, not a setting you can change yourself.
What Claude’s Microsoft 365 connector covers
Claude has its own connector for Microsoft 365, on every Claude plan including Free, and it is the easiest route for most work accounts. Anthropic’s documentation (opens in a new tab) lists what it can do: search and read SharePoint and OneDrive, Outlook mail and calendar, Teams meetings and chats, and, only once administrators turn on write actions, send mail, manage calendar events, update files and post Teams messages. To Do is not on the list. More on the connector is in Claude and Microsoft 365.
Two conditions matter for a personal to-do list. The connector needs a work or school account, and personal outlook.com, hotmail.com and live.com accounts are not supported. And a Microsoft Entra Global Administrator has to grant consent for the organisation. If your To Do list lives on a personal Microsoft account, this connector is not a route to it at all.
The To Do API underneath
Everything that does manage To Do from an assistant sits on the same API. The Microsoft Graph To Do API (opens in a new tab) has four things in it: task lists, tasks, checklist items inside a task, and linked resources that point back to where a task came from. Task lists and tasks support delta queries, so a client can fetch only what changed.
GET https://graph.microsoft.com/v1.0/me/todo/lists
GET https://graph.microsoft.com/v1.0/me/todo/lists/{listId}/tasks
POST https://graph.microsoft.com/v1.0/me/todo/lists/{listId}/tasks
{ "title": "Renew the parking permit" }The permission names are short and worth remembering: Tasks.Read to read, Tasks.ReadWrite to change anything. The list lists reference (opens in a new tab) shows both delegated permissions work for personal Microsoft accounts as well as work or school ones. That is why the community servers below can reach a personal list when Microsoft’s own services cannot.
Community MCP servers: what you are trusting
Search for a Microsoft To Do MCP server and you will find several open-source projects. None is recommended here, because the right one depends on code you should read yourself. They tend to share a shape: you register your own app with Microsoft, grant it Tasks.ReadWrite, sign in once, and the server keeps a token on your machine and runs locally for Claude Desktop, Claude Code or another client.
That shape carries four risks worth naming before you install one:
- The token is the whole list. A cached
Tasks.ReadWritetoken can read, change and delete every task in every list the account can see, whatever you asked the assistant to do. - The code runs as you. A server you install from a package registry runs with your user’s rights on your machine, and a later version can behave differently from the one you read.
- Task text is input. A shared list lets other people write text the model will read, which is the opening for prompt injection. See MCP security risks for how that plays out.
- Nobody signs the changes. Graph sees your account, so a task the assistant completed looks exactly like one you completed.
If you go ahead: read the source, pin the version, start with Tasks.Read if reading is all you need, keep your client’s approval prompt on for anything that writes, and remove the app’s consent from your Microsoft account when you stop using it. Writing a small server of your own, with only the three or four tools you actually want, is a reasonable alternative; how to build an MCP server walks through one.
If you connect one, start read-only
Whichever server you choose, the first session should prove it reads your lists correctly before it writes anything. These prompts show quickly how it understands them:
- “List my To Do lists and how many open tasks each one has.”
- “What is due this week, across all my lists?”
- “Which open tasks have every checklist item ticked?”
Then try one write you can check by eye in the To Do app: “Add ‘Book the MOT’ to my Errands list, due Friday.” Ask it to name every task it changed, because nothing in To Do will tell you afterwards which changes were the assistant’s and which were yours.
When a shared board fits better
Microsoft To Do is at its best as a personal list: groceries, renewals, the things you mean to do this week. The questions above get harder when the list is really shared work, with other people and an assistant all changing it, and you want to know who did what.
That is the job fenbs is built for. A fenbs board has four lanes, To Do, Next Up, In Progress and Completed, and three kinds of task: feature, enhancement and bug. An assistant joins over MCP with a browser sign-in: nothing to register, no token on disk to guard. It works with your role on the board, narrowed by the scopes you tick when you approve it, or with a narrower role of its own, and every change it makes is recorded in the history with its name. You can revoke its access under Settings without touching your own sign-in. If a to-do list you share with your assistant is what you are after, a shared AI to-do list walks through a day of it, and connecting Claude takes a couple of minutes.
Related
The two kinds of AI task tool: AI task manager vs task board. An official to-do MCP server for comparison: Todoist MCP with Claude. Habits for any MCP server you install: MCP security best practices.